Microsoft spoort aan: Move to phishing-resistant authentication before SMS and voice retire
We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027.
For more context on why Microsoft is moving to phishing-resistant authentication by default, please read our Microsoft Security Blog announcement.
SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing, SIM-swap, and replay attacks than passkeys. Moving to phishing-resistant methods gives your organization stronger security by default.
If you do have users enabled for SMS or voice, the required action is to move every one of those users off SMS and voice before February 1, 2027. Microsoft recommends passkeys — the default phishing-resistant credential in Microsoft Entra ID. Take the following steps:
The bottom line: every SMS and voice user must be on a phishing-resistant method — passkeys are recommended — before Microsoft-provided SMS and voice retire on February 1, 2027. Acting before September 1, 2026 lets you move users on your own schedule and avoid blocking prompts.
Bedrijvenweg 16
1424 PX De Kwakel
BTW: NL808876272B01
KVK: 33285810 Amsterdam
IBAN: NL18ABNA0561029806
ACM: 943723
ISO: ISC 528